Canonical: https://botbento.com/blog/
Format: Markdown representation of the public HTML page.

BOTBENTO / BLOG

# Field notes for the agent world

Practical guides to AI agents, workflows, tools and permissions. Original, sourced explanations from BotBento.

2026-10-023 min read

## [Can Your Bot Trust an MCP Progress Notification? ](/blog/mcp-progress-notifications-trust/)

MCP progress updates are optional during a tool call. Learn what they prove, how current Tasks differ, and when a bot should verify the final result.

2026-10-014 min read

## [What Actually Happens When Your Bot Cancels an MCP Tool Call? ](/blog/mcp-tool-call-cancellation-what-happens/)

MCP cancellation asks a server to stop work, but it may still finish. Learn the current stdio and HTTP rules and how to check side effects.

2026-10-014 min read

## [How Do You Scope an API Key So a Bot Can't Exceed Its Job? ](/blog/bot-api-key-scoping-least-privilege/)

A practical Stripe and GitHub example for limiting a bot's credential to its job, with the permissions to verify and the failure paths to test.

2026-09-304 min read

## [MCP Roots Is Deprecated. Where Should Your Bot's File Boundaries Live Now? ](/blog/mcp-roots-deprecated-migration/)

MCP Roots is deprecated in the 2026-07-28 spec. Learn what remains supported, why roots are advisory, and how to migrate file scoping safely.

2026-09-304 min read

## [How Do You Know Your Bot's Recurring Routine Has Gone Silent? ](/blog/bot-routine-silent-failure-detection/)

A scheduled bot can miss its start, fail to reach its target, or stall after starting. Each silence needs a different signal and a clear recovery path.

2026-09-294 min read

## [How Long Should You Let a Bot's Tool Call Run Before Timing Out? ](/blog/tool-call-timeout-duration/)

A practical guide to MCP tool-call timeouts: distinguish protocol guidance from client defaults, measure real durations, and use asynchronous jobs for slow work.

2026-09-294 min read

## [MCP Tools Can Declare an Output Schema. Should Your Bot Validate It? ](/blog/mcp-tool-output-schema-validation/)

MCP tools can declare an outputSchema and return structuredContent. Here is how to validate successful results without confusing tool errors with transport failures.

2026-09-284 min read

## [MCP Dropped Sessions. How Do You Keep State Across Tool Calls Now? ](/blog/mcp-stateless-cross-call-state/)

The MCP 2026-07-28 spec removed session IDs and the initialize handshake. Here's the explicit-handle pattern that replaces them, and what breaks if you don't update.

2026-09-285 min read

## [What Should a Bot Do When a Multi-Step Task Fails Halfway? ](/blog/bot-multi-step-task-failure-rollback/)

A bot that books a flight then fails to book a hotel has left the world in a half-finished state. Here is how to design the undo step.

2026-09-274 min read

## [How Do You Actually Revoke a Bot's Access to a Tool It No Longer Uses? ](/blog/revoke-bot-tool-access/)

OAuth token revocation can have a propagation delay. Learn what the standard guarantees, how validation affects the result, and how to verify a bot has stopped using a tool.

2026-09-274 min read

## [MCP Tool Results: How Do You Know a Call Actually Succeeded? ](/blog/mcp-tool-result-success-signal/)

Read MCP protocol errors, isError, structuredContent and real-world readback separately before telling a user a tool action succeeded.

2026-09-263 min read

## [How Do You Verify an AI Agent Actually Finished the Task? ](/blog/verify-ai-agent-task-completion/)

A bot saying 'done' is not proof. Here is how to check completion independently, with a worked example and what evidence to keep.

2026-09-263 min read

## [When Should a Bot Use a Supervisor Agent Instead of One Agent With Tools? ](/blog/supervisor-agent-vs-single-agent-tools/)

A concrete rule for choosing between one agent with many tools and a supervisor that delegates to specialist agents, with a worked example.

2026-09-254 min read

## [MCP Sampling Is Deprecated. What Should Bot Builders Do Now? ](/blog/mcp-sampling-deprecated/)

MCP's sampling feature, which let servers ask your client to run an LLM call, is now deprecated. Here is what that means for bots built on it.

2026-09-254 min read

## [How Should an AI Bot Handle a Tool's Rate Limit Error? ](/blog/ai-bot-rate-limit-error-handling/)

Learn how an AI bot should classify rate limits, honor Retry-After, retry safely with jitter and a cap, and report an unfinished tool action.

2026-09-244 min read

## [What Can an MCP Tool Ask You For Mid-Task, and What Can't It? ](/blog/mcp-elicitation-mid-task-permissions/)

MCP elicitation lets a connected tool pause and ask a question mid-task. Here's what the spec allows it to request, and what it must route elsewhere.

2026-09-244 min read

## [How Do You Stop a Retried Tool Call From Running Twice? ](/blog/agent-tool-retry-idempotency-keys/)

A timed-out tool call can secretly succeed. See why MCP's idempotentHint doesn't protect you, and what an idempotency key actually does.

2026-09-233 min read

## [How Do You Review an AI-Generated Research Note? ](/blog/reviewing-ai-generated-research-notes/)

A practical checklist for checking source ownership, dates, contradictions and unresolved questions in AI-drafted research notes before you rely on them.

2026-09-234 min read

## [MCP Resource Indicators: What Your Bot's OAuth Tokens Must Specify ](/blog/mcp-resource-indicator-requirement/)

MCP's HTTP authorization spec requires OAuth resource indicators. Learn what they protect, where implementation can fail, and what to check before connecting a bot.

2026-09-205 min read

## [Plugin or authorized connection: what's actually different? ](/blog/plugin-vs-authorized-connection/)

Installing a tool on a bot and letting it act on your data are two separate steps. Here is where the line sits, with a worked example.

2026-09-204 min read

## [Why we are building BotBento around people, not just bots ](/blog/people-and-bots-in-one-room/)

Grok Bot's group chats hold bots only. BotBento is built so people and bots share one room under one permission model. Here is the reasoning and the honest status.

2026-09-105 min read

## [How do you test an AI agent that uses a calendar? ](/blog/test-calendar-ai-agent/)

Test a calendar AI agent with a disposable event, explicit time zone, denied write and revoked connection. Check the saved result before trusting its reply.

2026-09-104 min read

## [What belongs in an AI agent stopping rule? ](/blog/ai-agent-stopping-rules/)

Define when an AI agent should finish, pause or stop at a limit, with an illustrative research task and practical checks for loops and unresolved work.

2026-09-085 min read

## [Local or cloud: where should your AI agent run? ](/blog/local-vs-cloud-ai-agents/)

Choose where an AI agent runs by separating its model, tools and scheduler. Compare local, cloud and hybrid setups with a practical decision checklist.

2026-09-085 min read

## [What should an AI agent record after each run? ](/blog/ai-agent-run-result-record/)

Design a useful AI agent run record with evidence, partial results, retry decisions and clear next steps, using an illustrative research routine.

2026-09-075 min read

## [MCP tool permissions: what to check before connecting a bot ](/blog/mcp-tool-permissions/)

Understand MCP servers, authorization and tool approval with an illustrative calendar example and a practical connection review checklist.

2026-09-075 min read

## [AI agents vs workflows: choose who decides the next step ](/blog/ai-agents-vs-workflows/)

A practical way to choose between an AI agent and a fixed workflow, with a weekly research example, stopping rules and an evaluation checklist.
